US2023262095A1PendingUtilityA1

Management of the security of a communicating object

Assignee: ORANGEPriority: Jun 26, 2020Filed: Jun 14, 2021Published: Aug 17, 2023
Est. expiryJun 26, 2040(~13.9 yrs left)· nominal 20-yr term from priority
H04L 63/20H04L 63/029H04L 12/66H04L 63/101H04L 67/12H04L 12/2809
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for managing a home gateway of a local area communication network. The gateway includes a plurality of components, called sensitive components. The network includes at least one communicating object able to be connected to the network via the gateway. The method includes acquiring at least one security rule relating to at least one interaction of the object with at least one of the components of the gateway; observing at least one interaction of the communicating object with at least one of the components of the gateway; and deciding, on the basis of the observation, on an action on the connected object.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 managing a home gateway of a local communication network, said gateway comprising a plurality of components, called sensitive components, said network comprising at least one communicating object able to be connected to said network via the gateway, the managing being performed by a management device and comprising:   observing at least one interaction of said communicating object with at least one of said components of said gateway; and   deciding, on the basis of said observation and on at least one security rule relating to at least one interaction of said object with at least one of said components of said gateway, on at least one action on said object.   
     
     
         2 . The method as claimed in  claim 1 , further comprising recording the object in a memory zone, called confinement zone, comprising at least one identification datum of the object and at least one security rule. 
     
     
         3 . The method as claimed in  claim 2 , further comprising removing the object from said confinement memory zone when a deconfinement criterion is met. 
     
     
         4 . The method as claimed in  claim 1 , further comprising acquiring said at least one security rule after a phase of detecting a connection of said communicating object to said gateway. 
     
     
         5 . The method as claimed in  claim 1 , further comprising acquiring said at least one security rule via a step of learning a behavior of the object. 
     
     
         6 . The method as claimed in  claim 1 , further comprising acquiring said at least one security rule on the basis of a characteristic datum of the object. 
     
     
         7 . The method as claimed in  claim 1 , wherein said at least one security rule associated with said communicating object comprises at least one element from among:
 a maximum amount of data that the communicating object is authorized to store in the gateway;   a maximum amount of data that the communicating object is authorized to exchange on one of the data buses of the gateway;   a maximum percentage of use of a processor of the gateway;   access to a communication module of the gateway; or   access to a software module of the gateway.   
     
     
         8 . The method as claimed in  claim 1 , further comprising detecting an interaction of said communicating object with at least one component contrary to said created security rule, and said action on the connected object comprises an action of the group consisting of:
 a modification of said at least one security rule;   blocking said interaction;   rejecting the object;   unpairing the object.   
     
     
         9 . The method as claimed in  claim 1 , wherein said at least one security rule is assigned a severity index, and the method comprises selecting the action on the object on the basis of this index. 
     
     
         10 . The method as claimed in  claim 1 , further comprising modifying said at least one security rule in the event of a detection of a modification in a context of the home gateway. 
     
     
         11 . A device for managing a home gateway of a local communication network, said gateway comprising a plurality of components, called sensitive components, said network comprising at least one communicating object able to be connected to said network via the gateway, the device comprising:
 a processor; and   a non-transitory computer readable medium comprising instructions stored thereon which when executed by the processor configure the device to:
 observe at least one interaction of said communicating object with at least one of said components of said gateway; and 
 decide, on the basis of said observation and on at least one security rule relating to at least one interaction of the object with at least one of said components of the gateway, on at least one action to be performed on said object. 
   
     
     
         12 . A home gateway including the device as claimed in  claim 11 . 
     
     
         13 . A non-transitory computer readable medium comprising a computer program stored thereon comprising instructions which when executed by a processor of a managing device configure the management device to perform a management method comprising:
 managing a home gateway of a local communication network, said gateway comprising a plurality of components, called sensitive components, said network comprising at least one communicating object able to be connected to said network via the gateway, the managing comprising:   observing at least one interaction of said communicating object with at least one of said components of said gateway; and   deciding, on the basis of said observation and on at least one security rule relating to at least one interaction of said object with at least one of said components of said gateway, on at least one action on said object.

Join the waitlist — get patent alerts

Track US2023262095A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.